Design Objective
Create a secure, scalable, and maintainable enterprise network capable of supporting business operations, communications, physical security, cloud services, and future organizational growth.
LWTech CSNT231/232 Networking I & II
A comprehensive enterprise network design project focused on infrastructure planning, network segmentation, physical security, wireless networking, redundancy, business continuity, and scalable enterprise architecture.
Project Background
The ASTL Network Design project focused on designing a complete enterprise network infrastructure for a mixed office and warehouse facility. The design supports employee workstations, warehouse devices, printers, VoIP phones, wireless access points, badge readers, security cameras, server infrastructure, and cloud-connected business services.
The project required planning both the physical and logical environment, including structured cabling, network racks, Internet connectivity, VLAN segmentation, firewall policy, wireless networking, cloud integration, redundancy, security, and future expansion.
Create a secure, scalable, and maintainable enterprise network capable of supporting business operations, communications, physical security, cloud services, and future organizational growth.
Project Summary
A three-week enterprise networking project completed as part of the Computer Security and Network Technology program at Lake Washington Institute of Technology.
Lake Washington Institute of Technology
Robert Havens
June 10, 2025
Three Weeks
Small-to-Medium Enterprise
Technical network report
UniFi U7 Pro Max
Primary & failover
Department & service segmentation
Dedicated voice network
Infrastructure Planning
The project addressed the physical, logical, wireless, security, and operational requirements of a complete enterprise network.
Designed infrastructure for a mixed office and warehouse facility with server rooms, network closets, employee workstations, wireless access points, VoIP phones, printers, cameras, and badge-access systems.
Planned Cat 6 cabling, fiber links, patch panels, keystone jacks, RJ45 termination standards, DAC cables, outdoor-rated cabling, rack infrastructure, and ISP handoff connections.
Designed segmented networks for accounting, development, office operations, security, management, marketing, records, sales, supply chain, servers, VoIP, guest Wi-Fi, and network management.
Planned firewall rules, ACLs, guest isolation, WPA3 Enterprise, RADIUS authentication, badge readers, CCTV, locked racks, visitor controls, and restricted access to sensitive spaces.
Platforms & Concepts
The design combined enterprise networking technologies, security controls, cloud services, wireless infrastructure, and physical security systems.
Identity, collaboration, authentication, and hosted business services.
Traffic control, segmentation, and least-privilege communication between network zones.
Physical security monitoring and controlled access to facility spaces.
Dream Machine Pro Max and Pro SE gateways supporting separate network and VoIP infrastructure.
Core aggregation, access switching, PoE delivery, fiber uplinks, and structured expansion.
Logical segmentation supporting security, performance, traffic management, and administration.
Separate voice traffic, dedicated gateway services, and quality-of-service planning.
Secure corporate wireless access with centralized RADIUS-backed authentication.
Enterprise access points, guest isolation, captive portal access, VLAN assignment, and roaming.
Core Design Decisions
The architecture was designed around resiliency, centralized management, secure segmentation, wireless availability, and long-term scalability.
Ziply Fiber served as the primary 10 Gbps connection, with Comcast Business providing failover connectivity. This supported business continuity if the primary connection became unavailable.
The topology combined star, logical bus, mesh, and hierarchical design elements to support access switching, core aggregation, redundancy, structured growth, and centralized management.
The wireless design included eight UniFi U7 Pro Max access points, WPA3 Enterprise for corporate access, RADIUS authentication, guest captive portal access, roaming, and VLAN isolation.
The design included locked racks, badge readers, CCTV, visitor controls, and access restrictions for sensitive areas including the server room, network closets, warehouse spaces, and secure storage areas.
Business Integration
The network design incorporated cloud and business services to support identity, collaboration, inventory management, remote access, backups, monitoring, and employee productivity.
SSO, RADIUS, VPN access, identity services, physical access control, and centralized monitoring.
Email, documentation, Teams collaboration, productivity applications, and OneDrive backups.
Identity integration, device monitoring, cloud resources, virtual machines, and infrastructure services.
Inventory management, order fulfillment, shipping, sales operations, and business workflow support.
Customer-facing company information, online ordering, public resources, and the organization’s web presence.
Applied Knowledge
The project applied networking, infrastructure, security, and documentation skills across a realistic enterprise design scenario.
Submitted Work
The following document was submitted as the final deliverable for the CSNT231/232 Networking I & II project.
Technical Design Report
A complete enterprise network design document covering floor plans, structured cabling, network hardware, topology, VLANs, device communication, firewall and security controls, storage, virtualization, wireless networking, business continuity, and physical security.
Project Reflection
This project reinforced how much planning is required before network implementation begins. A successful enterprise network extends well beyond switches, routers, and cabling. It must also consider business workflows, physical security, wireless coverage, redundancy, cloud integration, future growth, and long-term maintainability.
Designing ASTL from the ground up strengthened my understanding of how infrastructure decisions affect scalability, resiliency, security, and the day-to-day experience of both users and administrators.
Continue Exploring
Explore the rest of my portfolio to see additional systems administration, networking, cloud, and infrastructure projects, or reach out if you'd like to discuss my work.